Make the jdrive library embeddable for jsh (state-I/O override + credential injection + transpile) #36

Merged
ober merged 2 commits from feat/state-io-embed into main 2026-09-03 13:41:33 -04:00
Owner

What

Prepares jerboa-drive to be vendored by jerboa-shell-extras as the jdisk feature (follow-up PRs there). Three additions, no standalone behavior change beyond the noted improvement:

  • State-I/O indirection in (jdrive s3 drive): new exported *jdrive-state-io-override* parameter + jdrive-state-op dispatcher. All profile-state filesystem touchpoints (init/load/profile-status, generation marks) route through it. Default backend = plain filesystem; the default write op now uses the secure-output path for ALL state files (0600, symlink-safe) — profile config/vault files were previously written 0644.
  • Credential injection: new exported *jdrive-aws-credentials* parameter in (jdrive s3 config). When set to (access-key secret-key region token), jdrive-s3-status-json and s3-client-from-config pass explicit 'access-key:/'secret-key:/'token: keywords to S3Client, suppressing the internal aws-resolve-credentials call. Secrets never enter the process environment. (Keyword is 'token: per jerboa-aws s3/api kw-ref.)
  • Embed-aware default state root: with an override installed and no --state-dir flag, the default root is //embed/jdrive — it wins over JDRIVE_STATE_DIR (an ambient env var must not redirect a hardened host back to plaintext disk). An explicit flag still wins. Standalone jdrive is unaffected (the parameter defaults to #f).
  • transpile Makefile target: copies the (library ...) sources verbatim to lib/jdrive/**.sls (the extension Chez library search expects) for --libdirs consumers. lib/ is gitignored and removed by make clean.
  • Also exports with-unlocked-profile and s3-client-from-config; syncs the stale jpkg.sexp (1.8.4) and the CLI version string; VERSION 1.9.3 → 1.10.0.

Verification

  • make test: 79 checks green (74 existing + 5 new: parameter defaults, embed-root precedence, in-memory backend round-trip of init→load, status-json credential injection incl. session token, client construction with injected creds).
  • make binary + jdrive-bin version → 1.10.0; --help OK.
  • Standalone regression: JDRIVE_STATE_DIR=/tmp/... jdrive-bin s3 init writes plain files (now 0600); s3 profile-status reads them back.
  • make transpile + jerbuild exec with a lib-first libdir loads (jdrive s3 config)/(jdrive s3 drive) from the .sls tree and exercises the new parameters.
  • No new setenv (grep clean; only the pre-existing JDRIVE_PACK_SMALL_FILES flag).

Note: the jsh-side consumer lands in a jerboa-shell-extras PR that pins this branch tip in its source-lock.tsv; after merge that lock row should be updated to the merge commit.

## What Prepares jerboa-drive to be vendored by jerboa-shell-extras as the `jdisk` feature (follow-up PRs there). Three additions, no standalone behavior change beyond the noted improvement: - **State-I/O indirection** in `(jdrive s3 drive)`: new exported `*jdrive-state-io-override*` parameter + `jdrive-state-op` dispatcher. All profile-state filesystem touchpoints (init/load/profile-status, generation marks) route through it. Default backend = plain filesystem; the default `write` op now uses the secure-output path for ALL state files (0600, symlink-safe) — profile config/vault files were previously written 0644. - **Credential injection**: new exported `*jdrive-aws-credentials*` parameter in `(jdrive s3 config)`. When set to `(access-key secret-key region token)`, `jdrive-s3-status-json` and `s3-client-from-config` pass explicit `'access-key:`/`'secret-key:`/`'token:` keywords to `S3Client`, suppressing the internal `aws-resolve-credentials` call. Secrets never enter the process environment. (Keyword is `'token:` per jerboa-aws `s3/api` `kw-ref`.) - **Embed-aware default state root**: with an override installed and no `--state-dir` flag, the default root is `//embed/jdrive` — it wins over `JDRIVE_STATE_DIR` (an ambient env var must not redirect a hardened host back to plaintext disk). An explicit flag still wins. Standalone jdrive is unaffected (the parameter defaults to `#f`). - **`transpile` Makefile target**: copies the `(library ...)` sources verbatim to `lib/jdrive/**.sls` (the extension Chez library search expects) for `--libdirs` consumers. `lib/` is gitignored and removed by `make clean`. - Also exports `with-unlocked-profile` and `s3-client-from-config`; syncs the stale `jpkg.sexp` (1.8.4) and the CLI version string; VERSION 1.9.3 → 1.10.0. ## Verification - `make test`: 79 checks green (74 existing + 5 new: parameter defaults, embed-root precedence, in-memory backend round-trip of init→load, status-json credential injection incl. session token, client construction with injected creds). - `make binary` + `jdrive-bin version` → `1.10.0`; `--help` OK. - Standalone regression: `JDRIVE_STATE_DIR=/tmp/... jdrive-bin s3 init` writes plain files (now 0600); `s3 profile-status` reads them back. - `make transpile` + `jerbuild exec` with a lib-first libdir loads `(jdrive s3 config)`/`(jdrive s3 drive)` from the `.sls` tree and exercises the new parameters. - No new `setenv` (grep clean; only the pre-existing `JDRIVE_PACK_SMALL_FILES` flag). Note: the jsh-side consumer lands in a jerboa-shell-extras PR that pins this branch tip in its `source-lock.tsv`; after merge that lock row should be updated to the merge commit.
Make the jdrive library embeddable for jsh
All checks were successful
version-policy / required (pull_request) Successful in 3m49s
required-ci / required (pull_request) Successful in 4m36s
e7a2832294
Add a state-I/O indirection to (jdrive s3 drive): the new
*jdrive-state-io-override* parameter installs an alist backend
(exists?/read/write/ensure-dir/delete) that all profile-state
filesystem touchpoints now route through (init/load/status,
generation marks). The default backend keeps standalone behavior
and now writes every state file via the secure-output path (0600,
symlink-safe).

Add *jdrive-aws-credentials* to (jdrive s3 config): when set to
(access-key secret-key region token), jdrive-s3-status-json and
s3-client-from-config use explicit S3Client keywords instead of
aws-resolve-credentials, so hosts can inject credentials without
touching the process environment.

With an override installed, the default state root becomes
//embed/jdrive (explicit --state-dir still wins; JDRIVE_STATE_DIR
no longer redirects hardened hosts to plaintext disk).

Add a transpile Makefile target producing the Chez-loadable
lib/jdrive/**.sls tree for --libdirs consumers (jerboa-shell-extras).

VERSION 1.9.3 -> 1.10.0; jpkg.sexp synced (was stale at 1.8.4);
cli version string updated.
Merge origin/main (PR #37 manifest shard fixes) into feat/state-io-embed
All checks were successful
version-policy / required (pull_request) Successful in 3m47s
required-ci / required (pull_request) Successful in 4m34s
7fbccd6fbb
Conflicts were version-string only; kept 1.10.0. PR #37's drive-side
manifest/shard changes merged clean alongside the state-I/O override.
ober scheduled this pull request to auto merge when all checks succeed 2026-09-03 13:40:55 -04:00
ober merged commit 4bb71fdf57 into main 2026-09-03 13:41:33 -04:00
ober referenced this pull request from a commit 2026-09-03 13:41:34 -04:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
ober/jerboa-drive!36
No description provided.